IT Operations

IT Support Checklist for Opening a New Business

MSP Worx · 4 min read · Updated Oct 10, 2026

Starting a business is the one opportunity to set technology up properly before habits form and shortcuts become permanent. Most of the expensive problems businesses deal with at fifty employees were created in the first six months by decisions that seemed reasonable at the time.

This is the list, in the order the decisions actually need making.

Get the foundations right first

Domain name — registered to the business

Register it in the company's name, using a company email address, not a founder's personal account. This sounds trivial and is the single most common thing businesses have to untangle years later — particularly after a founder departs.

Enable registrar lock and auto-renewal. Expired domains take businesses offline and are occasionally bought by someone else within hours.

Email and productivity platform

Microsoft 365 or Google Workspace. Both are fine; pick one and commit, because running both produces duplicated files and split conversations permanently.

Two decisions worth making deliberately at the outset: buy the tier that includes device management and security features rather than the cheapest, because upgrading later means reconfiguring everything; and set up the tenant under a company administrative account rather than a personal one.

Identity and access from day one

Every person gets their own account. No shared logins, ever — they defeat every audit trail you will later need and they are impossible to unwind once established.

Turn MFA on before anyone has a chance to get used to working without it. Introducing it later is a change management exercise; introducing it now is simply how things work.

The decisions that are expensive to reverse

  1. Where files live. Decide once, communicate clearly, and be firm that work stored elsewhere is not backed up. Businesses that let this drift spend years consolidating.
  2. Naming conventions for accounts, devices and files. Trivial now, painful at scale.
  3. Whether you buy or lease hardware, and to what standard. Standardising on one or two device models makes everything downstream easier.
  4. Your accounting and line-of-business software. Migration later is disruptive and costly, so weigh this more carefully than the monthly price suggests.
  5. Whether anything runs on-premise. For most new businesses the answer should be no — cloud-first avoids capital cost, avoids a server room, and makes remote work a non-issue.

Security baseline for a new business

None of this is expensive, and all of it is much cheaper now than retrofitted:

  • MFA on every account, enforced rather than encouraged
  • A password manager, provisioned for everyone from the start
  • Device encryption enabled on every machine
  • Automatic updates configured and verified
  • Endpoint protection deployed
  • Backup for your cloud data — note that Microsoft and Google provide availability, not backup, and data protection is your responsibility under their shared responsibility models
  • A written payment verification procedure before you make your first payment, because invoice fraud targets new businesses specifically

That last item costs nothing and prevents the most expensive early failure mode. Any change to payment details gets verified by phone to a number you already hold, not the number on the invoice.

Know your obligations early

Compliance requirements are far cheaper to build in than to retrofit, and many new businesses do not realise they are covered:

  • Taking card payments brings PCI-DSS obligations. Using a hosted payment provider dramatically reduces what applies to you.
  • Health information brings HIPAA, and the definition is broader than clinical practice.
  • Tax preparation, lending, financial advice or arranging finance brings the FTC Safeguards Rule and a requirement for a written information security plan.
  • Holding personal data about New York residents brings SHIELD Act obligations regardless of sector.
  • Selling to larger companies increasingly means answering security questionnaires, and the answers are much easier if the controls exist already.
If your business…What appliesWhat to know
Takes card paymentsPCI-DSSA hosted payment provider dramatically reduces what applies
Handles health informationHIPAAThe definition is broader than clinical practice
Does tax preparation, lending, financial advice or arranges financeFTC Safeguards RuleA written information security plan is required
Holds personal data about New York residentsNY SHIELD ActApplies regardless of sector
Sells to larger companiesSecurity questionnairesFar easier to answer if the controls already exist

What you can defer

Equally important, since early-stage money is finite:

  • A managed IT agreement, generally, until around ten employees — though an initial setup engagement is worth paying for even if ongoing support is not
  • Advanced security tooling beyond the baseline above
  • A vCIO or formal strategy function
  • Custom software of any kind. Use standard products until you are certain they genuinely do not fit
  • On-premise anything

A sensible first-year sequence

  1. Register the domain to the business
  2. Choose and configure the productivity platform, on a tier that includes security tooling
  3. Set up individual accounts with MFA and a password manager
  4. Standardise on device hardware and get encryption and updates enforced
  5. Decide where files live and communicate it
  6. Arrange backup for cloud data
  7. Write the payment verification procedure
  8. Establish what compliance obligations apply
  9. Document what you have, even briefly — it will never be easier than now

A weekend of deliberate decisions at the start avoids years of accumulated workarounds. The businesses that struggle at fifty people are rarely the ones that spent more at five — they are the ones that decided nothing and let it accumulate.

Sources

  1. Federal Trade Commission — FTC Safeguards Rule: What Your Business Needs to Know
  2. New York State Senate — New York General Business Law § 899-BB: Data security protections
  3. PCI Security Standards Council — Merchant Resources
  4. Microsoft Learn — Shared responsibility in the cloud
  5. FBI Internet Crime Complaint Center (IC3) — Business Email Compromise: The $50 Billion Scam (Alert I-060923-PSA)

Want a straight answer for your business?

Talk to an advisor about your environment. No pitch, no obligation.